Answered: [Security threat] tags are not sanitized in extra question field

Post date: 2020-07-01 00:44:51
Views: 146

Hey q2apro, I think you are testing the default q_view_extra($q_view); function.

The default function is still safe. But if you pull the content from the databse, it's not safe.

First, look! The script is stored in database.

database

Second, if create a function to pull that content form the datase:

public function q_item_extra($q_item)
{
$postidz = $q_item'raw']'postid'];
$extra = qa_db_read_one_value(qa_db_query_sub(
       'SELECT content FROM ^postmetas WHERE title="qa_q_extra" AND postid=#',
        $postidz
   ), true);
 
 //$extra = $q_item'extra']'content'];
 
        $this->output('My info:'.$extra);   
   
}

Here's the result:

test

I hope you'll get my point.

Please click Here to read the full story.
 
Other Top and Latest Questions:
Activist investor Elliott takes more than $2 billion stake in Workday, backs leadership
Images of Trump and Jeffrey Epstein projected on Windsor Castle as U.S. president visits the UK
Eli Lilly aims to bring more manufacturing home — plus, the good and bad among our industrials
Asia markets trade mixed after Wall Street declines as investors await Fed decision
China keeps tight grip on rare earths, costing at least one company 'millions of euros'
From royal pomp to Epstein embarrassment: Trump's UK state visit in pictures
CNBC's The China Connection newsletter: China’s attempt to pivot away from the U.S. starts with this trading hub
The UK's top fintech companies: 2025
Three things Britain wants from Trump's state visit — aside from business deals
Stock futures are little changed as traders await key Fed rate outlook: Live updates